SB2026090989 - Multiple vulnerabilities in Adobe Experience Manager



SB2026090989 - Multiple vulnerabilities in Adobe Experience Manager

Published: September 9, 2026

Security Bulletin ID SB2026090989
CSH Severity
High
Patch available
YES
Number of vulnerabilities 108
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 1% Medium 3% Low 96%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 108 vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2026-75715)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


2) Cross-site scripting (CVE-ID: CVE-2026-75679)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


3) Cross-site scripting (CVE-ID: CVE-2026-75694)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


4) Cross-site scripting (CVE-ID: CVE-2026-75693)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


5) Cross-site scripting (CVE-ID: CVE-2026-75692)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


6) Cross-site scripting (CVE-ID: CVE-2026-75691)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


7) Cross-site scripting (CVE-ID: CVE-2026-75690)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


8) Cross-site scripting (CVE-ID: CVE-2026-75687)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


9) Cross-site scripting (CVE-ID: CVE-2026-75685)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


10) Cross-site scripting (CVE-ID: CVE-2026-75683)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


11) Cross-site scripting (CVE-ID: CVE-2026-75681)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


12) Cross-site scripting (CVE-ID: CVE-2026-75680)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


13) Cross-site scripting (CVE-ID: CVE-2026-75678)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


14) Cross-site scripting (CVE-ID: CVE-2026-75629)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


15) Cross-site scripting (CVE-ID: CVE-2026-75677)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


16) Cross-site scripting (CVE-ID: CVE-2026-75675)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


17) Cross-site scripting (CVE-ID: CVE-2026-75674)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


18) Cross-site scripting (CVE-ID: CVE-2026-75672)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


19) Cross-site scripting (CVE-ID: CVE-2026-75671)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


20) Cross-site scripting (CVE-ID: CVE-2026-75670)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


21) Cross-site scripting (CVE-ID: CVE-2026-75669)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


22) Cross-site scripting (CVE-ID: CVE-2026-75668)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


23) Cross-site scripting (CVE-ID: CVE-2026-75718)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


24) Cross-site scripting (CVE-ID: CVE-2026-75717)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


25) Cross-site scripting (CVE-ID: CVE-2026-75716)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


26) Cross-site scripting (CVE-ID: CVE-2026-19713)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


27) Cross-site scripting (CVE-ID: CVE-2026-75635)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


28) Cross-site scripting (CVE-ID: CVE-2026-75714)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


29) Cross-site scripting (CVE-ID: CVE-2026-75660)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


30) Resource exhaustion (CVE-ID: CVE-2026-18401)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the non-blocking (async) JSON parser in jackson-core bypasses the maxNumberLength constraint (default: 1000 characters) defined in StreamReadConstraints. A remote attacker can send JSON with arbitrarily long numbers through the async parser API and exhaust CPU resources, leading to a denial of service condition. 


31) Input validation error (CVE-ID: CVE-2026-75726)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass security features.

The vulnerability exists due to improper input validation in Adobe Experience Manager when processing crafted input. A remote user can provide crafted input to bypass security features.

User interaction is required.


32) Cross-site scripting (CVE-ID: CVE-2026-71565)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


33) Cross-site scripting (CVE-ID: CVE-2026-72626)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


34) Cross-site scripting (CVE-ID: CVE-2026-72627)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


35) Cross-site scripting (CVE-ID: CVE-2026-19479)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


36) Cross-site scripting (CVE-ID: CVE-2026-19612)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


37) Cross-site scripting (CVE-ID: CVE-2026-19644)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


38) Cross-site scripting (CVE-ID: CVE-2026-75667)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


39) Cross-site scripting (CVE-ID: CVE-2026-75666)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


40) Cross-site scripting (CVE-ID: CVE-2026-75661)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


41) Cross-site scripting (CVE-ID: CVE-2026-75659)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


42) Cross-site scripting (CVE-ID: CVE-2026-75636)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


43) Cross-site scripting (CVE-ID: CVE-2026-75657)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


44) Cross-site scripting (CVE-ID: CVE-2026-75652)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


45) Cross-site scripting (CVE-ID: CVE-2026-75651)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


46) Cross-site scripting (CVE-ID: CVE-2026-75647)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


47) Cross-site scripting (CVE-ID: CVE-2026-75646)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


48) Cross-site scripting (CVE-ID: CVE-2026-75644)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


49) Cross-site scripting (CVE-ID: CVE-2026-75643)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


50) Cross-site scripting (CVE-ID: CVE-2026-75642)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


51) Cross-site scripting (CVE-ID: CVE-2026-75640)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


52) Cross-site scripting (CVE-ID: CVE-2026-75639)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


53) Cross-site scripting (CVE-ID: CVE-2026-75637)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


54) Cross-site scripting (CVE-ID: CVE-2026-75713)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


55) Cross-site scripting (CVE-ID: CVE-2026-75741)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


56) Cross-site scripting (CVE-ID: CVE-2026-75724)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to escalate privileges.

User interaction is required.


57) Cross-site scripting (CVE-ID: CVE-2026-75722)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


58) Cross-site scripting (CVE-ID: CVE-2026-75720)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to escalate privileges.

User interaction is required.


59) Cross-site scripting (CVE-ID: CVE-2026-75719)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to escalate privileges.

User interaction is required.


60) Stored cross-site scripting (CVE-ID: CVE-2025-64542)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


61) Cross-site scripting (CVE-ID: CVE-2026-71357)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


62) Division by zero (CVE-ID: CVE-2026-27222)

CWE-ID: CWE-369 - Divide By Zero

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the application.

The vulnerability exists due to a divide by zero error when handling files. A remote attacker can trick the victim into opening a specially crafted file and crash the application. 


63) Cross-site scripting (CVE-ID: CVE-2025-64584)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


64) Cross-site scripting (CVE-ID: CVE-2026-75742)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


65) Cross-site scripting (CVE-ID: CVE-2025-64588)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


66) Cross-site scripting (CVE-ID: CVE-2025-64589)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


67) Cross-site scripting (CVE-ID: CVE-2026-75740)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


68) Cross-site scripting (CVE-ID: CVE-2026-71356)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


69) Stored cross-site scripting (CVE-ID: CVE-2025-64610)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.


70) Cross-site scripting (CVE-ID: CVE-2025-64618)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


71) Cross-site scripting (CVE-ID: CVE-2026-75739)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


72) Stored cross-site scripting (CVE-ID: CVE-2026-27227)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data. A remote user can inject and execute arbitrary HTML and script code in user's browser in context of vulnerable website.


73) Cross-site scripting (CVE-ID: CVE-2026-71440)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


74) Cross-site scripting (CVE-ID: CVE-2026-75738)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


75) Cross-site scripting (CVE-ID: CVE-2026-75737)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


76) Cross-site scripting (CVE-ID: CVE-2026-75736)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


77) Heap-based buffer overflow (CVE-ID: CVE-2026-27238)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


78) Cross-site scripting (CVE-ID: CVE-2026-75735)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


79) Cross-site scripting (CVE-ID: CVE-2025-64830)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


80) Cross-site scripting (CVE-ID: CVE-2026-75725)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


81) Cross-site scripting (CVE-ID: CVE-2026-75727)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


82) Cross-site scripting (CVE-ID: CVE-2026-75712)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


83) Cross-site scripting (CVE-ID: CVE-2026-75696)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


84) Cross-site scripting (CVE-ID: CVE-2026-75711)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


85) Cross-site scripting (CVE-ID: CVE-2026-75710)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


86) Cross-site scripting (CVE-ID: CVE-2026-75709)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


87) Cross-site scripting (CVE-ID: CVE-2026-75708)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


88) Cross-site scripting (CVE-ID: CVE-2026-75707)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


89) Cross-site scripting (CVE-ID: CVE-2026-75706)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


90) Cross-site scripting (CVE-ID: CVE-2026-75705)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


91) Cross-site scripting (CVE-ID: CVE-2026-75704)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


92) Cross-site scripting (CVE-ID: CVE-2026-75702)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


93) Cross-site scripting (CVE-ID: CVE-2026-75701)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


94) Cross-site scripting (CVE-ID: CVE-2026-75700)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


95) Cross-site scripting (CVE-ID: CVE-2026-75695)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


96) Cross-site scripting (CVE-ID: CVE-2026-79905)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


97) Cross-site scripting (CVE-ID: CVE-2026-75734)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


98) Cross-site scripting (CVE-ID: CVE-2026-75733)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


99) Cross-site scripting (CVE-ID: CVE-2025-64838)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


100) Cross-site scripting (CVE-ID: CVE-2026-75731)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


101) Cross-site scripting (CVE-ID: CVE-2026-75730)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


102) Cross-site scripting (CVE-ID: CVE-2026-71388)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to DOM-based cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


103) Cross-site scripting (CVE-ID: CVE-2025-64854)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


104) Cross-site scripting (CVE-ID: CVE-2026-75729)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


105) Cross-site scripting (CVE-ID: CVE-2025-64866)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


106) Cross-site scripting (CVE-ID: CVE-2025-64868)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to stored cross-site scripting in Adobe Experience Manager when processing crafted content. A remote user can inject crafted script to execute arbitrary code.

User interaction is required.


107) Out-of-bounds write (CVE-ID: CVE-2026-27258)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in Adobe DNG Software Development Kit (SDK) when parsing input. A remote attacker can trick the victim into opening crafted content to cause a denial of service.

User interaction is required to process crafted content.


108) XML External Entity injection (CVE-ID: CVE-2025-54988) Exploited

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input within the PDF parser module. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


Remediation

Install update from vendor's website.